Run device attestation after enrollment and periodically (Desktop)
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 35/100
Research direction
Start by tracing the desktop enrollment flow and the existing periodic posture-data checks, including disk-encryption checks. Then follow the core's EK certificate validation and device-status updates; done means all listed enrollment, periodic, failure, fingerprint, CA, and unsupported-client scenarios produce the specified statuses and metadata.
Written by the indexing model from the issue text.
Description
User story
As an admin, I want each device to be attested when it's enrolled and periodically afterwards, so that its attestation status is always current.
Acceptance criteria
- The desktop client runs attestation automatically after the device is enrolled, with no user action.
- The client re-runs attestation periodically, using the same interval and mechanism as the existing posture data checks (e.g. disk encryption).
- The core validates the device's EK certificate against the EK CA database, including manually added CAs:
- The certificate chains to a known CA → Attested.
- The attestation is valid but the CA is unknown → Unrecognized (#3734 ).
- There's no TPM, the attestation is invalid, or the client doesn't support attestation → Not attested.
- Each successful attestation stores or updates the attestation date, certificate owner and fingerprint.
- If a previously attested device fails a later attestation, its status changes to Not attested.
- If the device's fingerprint changes, its verification status is reset to Not verified.
Test scenarios
- Enroll a device with a supported TPM → it becomes Attested, with a date and fingerprint, without any user action.
- Enroll a device with no TPM → it becomes Not attested.
- Enroll a device with a TPM from an unknown CA → it becomes Unrecognized.
- Wait for the next periodic check → the attestation date updates.
- Make attestation fail on an attested device (e.g. disable the TPM) → at the next periodic check it becomes Not attested.
- A verified device reports a different fingerprint → it becomes Not verified.
- An older client without attestation support → the device is Not attested.
Notes
- Use the device's WireGuard public key as the attestation nonce. This binds the attestation to the client configuration.
- Attestation results will be part of every config polling request and stored in Core. Separate #3782
- Dominant language
- Rust
- Stars
- 2.9k
- Forks
- 119
- Avg merge
- 1d 2h
- Merged PRs (30d)
- 61
Getting set up
- Ships a Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from DefGuard/defguard
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
All issues in DefGuard/defguard
Similar issues
-
awaiting-response bug needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
wildcard/caro#1562 · 1 comment ·
Maintainers usually reply within 3 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
objectionary/sodg.rs#301 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
HakanSeven12/OpenCADStudio#1706 · 1 comment ·
Maintainers usually reply within 1 day
-
[Bug] Completion info popup (.cm-completionInfo) ignores the configured editor fontPossibly taken A pull request linked to this issue is open or already merged. Openbug user-priority/P2
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
rescript-lang/rescript#8765 ·
Maintainers usually reply within 1 day